{"podcast":{"title":"GRC Uncensored","slug":"grc-uncensored-7039393","podcast_index_feed_id":7039393,"rss_url":"https://feeds.acast.com/public/shows/6702dcb9c88f09c3e0b9a10a","website_url":"https://feeds.acast.com/public/shows/grc-uncensored","image_url":"https://assets.pippa.io/shows/6702dcb9c88f09c3e0b9a10a/1741868280073-98dc972f-f9c8-433b-ab33-a977b7f15a82.jpeg","author":"Elliot Volkman and Troy Fine","episode_count":24,"summary":"GRC Uncensored is an experimental podcast designed to elevate real conversations with GRC professionals, auditors, regulators, and those building programs around it. Your hosts are Troy Fine and Elliot Volkman. Hosted on Acast. See acast.com/privacy for more information.","last_synced_at":"2026-07-23T06:20:29.446813+00:00","page_url":"https://stenobird.com/podcast/grc-uncensored-7039393"},"episode":{"title":"Third-Party Risk Management: When to Accept or Reject Vendor Documentation","slug":"third-party-risk-management-when-to-accept-or-reject-vendor-documentation","published_at":"2025-03-27T10:30:00+00:00","page_url":"https://stenobird.com/podcast/grc-uncensored-7039393/third-party-risk-management-when-to-accept-or-reject-vendor-documentation","show_page_url":"https://stenobird.com/podcast/grc-uncensored-7039393","url":"https://grcpod.substack.com/","audio_url":"https://sphinx.acast.com/p/open/s/6702dcb9c88f09c3e0b9a10a/e/67e4a41cd6912226b5d693e9/media.mp3","summary":"On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest Stanley Krochik , a now seasoned GRC professional and former city security program manager, to discuss the realities of third-party risk Management (TPRM). The conversation focused on the growing issue of low-quality audits, the challenge of assessing vendor security postures, and the dilemma risk managers face when reviewing third-party documentation. 04:43 The Importance of Third Party Risk Management 05:45 Challenges with Low Quality Audits 07:45 Evaluating SOC 2 Reports 12:55 Issues with Sales-Focused GRC Tools 14:44 The Need for Better Compliance Programs 27:50 High-Risk Vendor Architecture Review 29:07 SOC 2 Reports and Vendor Risk Management 31:50 Challenges with SOC 2 and Auditor Quality 36:49 Financial Impact of Data Breaches 38:10 Differences in Security Between Old and New Systems 47:43 Proactive vs. Reactive Security Measures Hosted on Acast. See acast.com/privacy for more information.","meta_description":"On a recent episode of GRC Uncensored, host Troy Fine and producer Elliot Volkman were joined by guest Stanley Krochik , a now seasoned GRC professional a…","key_points":[],"chapters":[],"topics":[],"duration_seconds":3223,"processing_state":"not_requested","actions":[{"name":"request_transcript","method":"POST","url":"https://stenobird.com/v1/public/podcasts/grc-uncensored-7039393/episodes/third-party-risk-management-when-to-accept-or-reject-vendor-documentation/transcription-requests","description":"Idempotently request low-priority transcript generation for this episode."},{"name":"read_markdown","method":"GET","url":"https://stenobird.com/podcast/grc-uncensored-7039393/third-party-risk-management-when-to-accept-or-reject-vendor-documentation.md","description":"Read the agent-friendly Markdown representation of this episode resource."}]}}